github-release-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external GitHub sources, such as commit messages and pull request descriptions, to automate the generation of changelogs and release notes.
  • Ingestion points: Data is fetched via gh api repos/:owner/:repo/compare/... and gh pr list in SKILL.md.
  • Boundary markers: No explicit delimiters or instruction-ignore warnings are used when interpolating command outputs into variables like $CHANGELOG.
  • Capability inventory: The skill possesses extensive capabilities, including executing shell commands (Bash), writing files (Write), and creating pull requests via the GitHub CLI.
  • Sanitization: There is no evidence of sanitization or filtering for the external content retrieved from repository history.
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the claude-flow and claude-flow@alpha utility packages from the npm registry.
  • Evidence: Multiple instances of npx claude-flow and npx claude-flow@alpha are used throughout SKILL.md for release orchestration.
  • [COMMAND_EXECUTION]: Executes shell commands and utilizes the GitHub CLI (gh) to perform repository management and deployment tasks.
  • Evidence: Frequent use of Bash calls in SKILL.md for git operations, version bumping, and API interactions.
  • [DYNAMIC_EXECUTION]: Uses dynamic task orchestration and agent spawning to coordinate complex release workflows across multiple environments.
  • Evidence: Use of mcp__claude-flow__task_orchestrate and mcp__claude-flow__agent_spawn in SKILL.md to define agent roles and execution strategies at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — github-release-management